Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
- Sarah Gooding
Socket has joined the OpenJS Foundation’s new Security Stewardship Program as an inaugural partner, helping fund vulnerability research, triage, patching, and security releases across the JavaScript ecosystem.
The program launches with an initial focus on Node.js, where the security workload is growing faster than the funding available to support it.
“AI is driving a sharp rise in vulnerability reports, pushing many open source projects to shut down their bug bounty programs. The bottleneck is now remediation,” Socket CEO Feross Aboukhadijeh said. “We’re backing the SSP to make that work paid and sustainable across the Node.js ecosystem.”
Bug Bounty Funding Is Drying Up Across the Industry
Projects and vendors are already changing how they handle the growing volume of vulnerability reports. curl shut down its bug bounty program at the end of January after low-quality, often AI-generated reports flooded its small security team. It later reopened HackerOne for vulnerability reports, but did not restore bounty payments. In July, GitHub restructured its bug bounty program by adding a signal requirement to reduce low-effort and AI-generated submissions and reserving its highest rewards for an invitation-only program.
The pressure extends beyond bounty triage. Canonical is moving Ubuntu kernel updates to a weekly release cadence as AI-assisted research contributes to a sharp rise in CVEs, replacing its four-week regular and two-week security cycles with overlapping two-week cycles.
In April, the Node.js project paused its security bug bounty program after the Internet Bug Bounty initiative stopped providing the external funding that had supported rewards since 2016. Node.js continued accepting and triaging reports through HackerOne, but could no longer offer researchers monetary rewards.
The funding loss arrived during a sharp increase in AI-assisted vulnerability research. According to the OpenJS Foundation’s Q2 2026 security update, the Node.js security team received 352 HackerOne reports over the preceding two years. In February 2026, monthly volume jumped 4.6 times, followed by 65 reports in March alone.
Many of those submissions were invalid, duplicated, or outside the Node.js threat model. Separating real vulnerabilities from junk and slop reports still takes maintainer time, and valid findings can require fixes across several supported release lines.
Funding Discovery and Remediation
The Security Stewardship Program uses a pooled funding model that divides contributions equally between bug bounties for security researchers and direct support for maintainers doing triage, patching, backporting, and release work. It also provides vulnerability disclosure and CVE coordination through the OpenJS Foundation, which is a CVE Numbering Authority. The Node.js Technical Steering Committee provided input during the program’s design.
The program begins with Node.js, but the model addresses a problem across open source: vulnerability discovery is accelerating, while triage and remediation still depend on a small number of people with limited time. Paying for both is a concrete way for companies that depend on JavaScript infrastructure to help secure it.
Organizations interested in participating can contact the OpenJS Foundation to learn more about joining the Security Stewardship Program.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.